Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Newbie question
From: Chris Garrigues <cwg @ DeepEddy . Com>
Date: Tue, 17 Sep 1996 15:25:36 -0500
To: "<" <mdr @ vodka . sse . att . com>
Cc: smith @ sctc . com (Rick Smith), firewalls @ GreatCircle . COM, msmith @ quix . robins . af . mil, cwg @ deepeddy . DeepEddy . Com
In-reply-to: Your message of "Tue, 17 Sep 1996 10:48:27 EDT." <199609171646 . LAA14476 @ ihig2 . firewall . lucent . com>

mdr @
 vodka .
 sse .
 att .
 com said:
> I prefer option 4. "place it own its own subnet."

>                                                                   
> [Internet]---[FWALL]----[Company Net]---[SQL Server]
>                 |   
>                 |                           
>               [Webserver]                                     

I'm curious about something.  Why is the above map considered 
better than this map:

[Internet]---[Filtering Router]---+---[Firewall]---[Company Net]
                                  |
                              [Webserver]

I see maps like yours all the time, but I'm uneasy about real 
routing happening on my firewall.  It just seems to me like
there's potential risk in running routing software on a firewall.

Is the argument that there's more expense due to the additional
hardware?  I hope we all agree that's a bogus security argument.
Otherwise, we'd just put the webserver on the firewall itself.

For that matter, until I got on this list, I had thought one
of the defining characteristics of a firewall was that it *never*
routed packets, but I keep seeing these discussions about how
to configure a firewall to not let SYN packets through...If
a firewall never routes packets, that can't happen.

Firewalls that I've built have never routed anything.  Instead they
run socks and various proxies.

Chris


-- 
Chris Garrigues                    O-              cwg @
 DeepEddy .
 Com
  Deep Eddy Internet Consulting                     +1 512 432 4046
  609 Deep Eddy Avenue
  Austin, TX  78703-4513              http://www.DeepEddy.Com/~cwg/


Attachment: pgpLAVQZMK4Ul.pgp
Description: PGP signature


References:
Indexed By Date Previous: Re: Internet policy
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Next: RE: Newbie question
From: Dan Tshin <dtshin @ bulldog . ca>
Indexed By Thread Previous: Re: Newbie question
From: "<"<@lucent.lucent.com:mdr @ vodka . sse . att . com>
Next: RE: Newbie question
From: Lawrence Lerner <lernerl @ metamor . com>

Google
 
Search Internet Search www.greatcircle.com